X-O36
o365spray
Username enumeration and password-spraying tool targeting Microsoft O365/Entra ID authentication endpoints, with built-in lockout throttling.
OVERVIEW
o365spray (0xZDH/o365spray) is a Python tool purpose-built against Microsoft O365/Entra ID authentication surfaces. Its `--validate` module confirms a domain is backed by O365, `--enum` checks whether individual usernames exist using techniques like Autologon, OAuth2, and RST endpoint responses, and `--spray` runs a password spray against a supplied username list.
What sets it apart from generic spray tools is that it is explicitly documented, in its own README, as account-lockout aware: the enumeration modules that make one authentication attempt per user will automatically reset the tenant's lockout timer before a subsequent spray runs in the same execution, and the tool exposes `--count` and `--lockout` flags so an operator can pace attempts to a client's actual lockout policy.
USE CASES
Practical use cases
- 01
Validating that a target domain is backed by Microsoft O365/Entra ID before investing further recon effort.
- 02
Enumerating which addresses in a harvested list correspond to real, valid tenant accounts.
- 03
Running rate-limited password spraying against a vetted, client-approved password list.
- 04
Routing enumeration and spray traffic through FireProx-style rotating endpoints to test detection coverage rather than raw success rate.
QUICK START
Once password-spraying against a client's O365/Entra ID tenant is explicitly authorized, to validate the tenant, enumerate valid usernames, and spray a vetted password list against real accounts.
- Confirm the specific domain, username list, and password list are all within the signed authorization before running anything against it.
- Validate the tenant: `o365spray --validate --domain target.com`.
- Enumerate valid usernames against the harvested list: `o365spray --enum -U usernames.txt --domain target.com`.
- Spray only with the client-approved passwords, respecting the tenant's real lockout threshold: `o365spray --spray -U usernames.txt -P passwords.txt --count 1 --lockout 10 --domain target.com`.
o365spray --enum -U usernames.txt --domain target.comBEFORE YOU RUN IT
What to check before running it
Password spraying targets real end-user accounts, not just infrastructure — it must be explicitly authorized in writing, with the client's actual lockout policy and password list agreed in advance, separately from any infrastructure-only recon authorization.
Getting `--count`/`--lockout` wrong locks out real users and generates helpdesk tickets; always pace spraying below the tenant's documented lockout threshold and coordinate timing with the client's SOC.
Enumeration and spray attempts appear as authentication events in Entra ID sign-in logs (often as many failed sign-ins from a single source); agree with the client on what to expect there for the blue-team debrief.